top of page
perceptive_background_267k.jpg

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows una…

Published:

3 augustus 2026 om 00:00:00

Alert date:

3 augustus 2026 om 17:06:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Web Technologies

A path traversal vulnerability exists in OpenWrt's luci-app-bmx7 package prior to commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd. The flaw resides in the bmx7-info CGI script and allows unauthenticated attackers to read arbitrary files outside the configured runtimeDir. Exploitation is achieved by supplying directory traversal sequences in the HTTP query string, enabling escape from the intended directory boundary. Sensitive files accessible to the CGI process can be read without any authentication. The vulnerability affects OpenWrt routers and embedded devices running the affected luci-app-bmx7 package. A fix has been committed and is referenced by the specific commit hash. The issue is documented in a GitHub Security Advisory and a VulnCheck advisory. No active exploitation has been publicly confirmed at this time, but the unauthenticated nature of the attack raises the criticality level.

Technical details

Mitigation steps:

Affected products:

OpenWrt luci-app-bmx7

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page